General

  • Target

    356363979-8832437294380 20241206 908376677.exe

  • Size

    1.0MB

  • Sample

    240617-qv8xcaxclq

  • MD5

    306861cd3f8c4a9c9a818c5348a14040

  • SHA1

    5dfd78ad88a94078a38978984d81b3926f479ac7

  • SHA256

    378dc7dc73eb893bd2d6878ca5c2da5cb1bb16bf0aee4e94352a4b7ca8da7832

  • SHA512

    b4d8408be102dcd50adaa3de66f77c7a31a57ee615ec2bc1a1ec255246d93e6989c7f421bad384deb667a6bc90a1bafad5815b46b5306c47c075b1f355d32628

  • SSDEEP

    12288:uVqi8tTaU9nxYoWo51/QZtAAm5WzgNYTpuXAyRavD7R5GHYG2ucIPC92:lbnKoWt6AzqQyGlGV9z

Malware Config

Extracted

Family

formbook

Version

4.1

Campaign

na10

Decoy

tetheus.com

ventlikeyoumeanit.com

tintbliss.com

rinabet357.com

sapphireboutiqueusa.com

abc8bet6.com

xzcn3i7jb13cqei.buzz

pinktravelsnagpur.com

bt365038.com

rtpbossujang303.shop

osthirmaker.com

thelonelyteacup.com

rlc2019.com

couverture-charpente.com

productivagc.com

defendercarcare.com

abcentixdigital.com

petco.ltd

oypivh.top

micro.guru

Targets

    • Target

      356363979-8832437294380 20241206 908376677.exe

    • Size

      1.0MB

    • MD5

      306861cd3f8c4a9c9a818c5348a14040

    • SHA1

      5dfd78ad88a94078a38978984d81b3926f479ac7

    • SHA256

      378dc7dc73eb893bd2d6878ca5c2da5cb1bb16bf0aee4e94352a4b7ca8da7832

    • SHA512

      b4d8408be102dcd50adaa3de66f77c7a31a57ee615ec2bc1a1ec255246d93e6989c7f421bad384deb667a6bc90a1bafad5815b46b5306c47c075b1f355d32628

    • SSDEEP

      12288:uVqi8tTaU9nxYoWo51/QZtAAm5WzgNYTpuXAyRavD7R5GHYG2ucIPC92:lbnKoWt6AzqQyGlGV9z

    • Formbook

      Formbook is a data stealing malware which is capable of stealing data.

    • Formbook payload

    • Deletes itself

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks